IT Governance, Risk, and Compliance Manager

🕒 il y a 2 mois

🇧🇬 Bulgarie – Télétravail

⏰ Temps Plein

🟠 Senior

🔴 Expert

🚔 Conformité

👻 Score fantôme 33%

infoinfo

🗣️🇺🇸🇬🇧 Anglais requis

Postuler Maintenant
Trouver des Emplois à Distance Similaires

📊 Vérifiez votre score de CV pour ce poste

Améliorez vos chances d'obtenir un entretien en vérifiant votre score de CV avant de postuler.

Logo of emerchantpay

emerchantpay

201 - 500 employés

💼 Conseil

📦 Logistique

✈️ Tourisme

Consulting • Logistics • Travel

emerchantpay est un fournisseur de solutions de paiement global offrant des services de paiement en ligne et en magasin de bout en bout. Spécialisé dans l'intégration fluide des paiements, emerchantpay propose des paiements en ligne, des terminaux point de vente, des services d'émission et d'acquisition de cartes. Avec un réseau d'acquisition mondial robuste, l'entreprise permet aux entreprises d'accepter une large gamme de méthodes de paiement et de devises, améliorant ainsi l'expérience client et l'efficacité opérationnelle. Emerchantpay offre également des outils de gestion des risques et de la fraude, des méthodes de paiement globales et des rapports de paiement détaillés pour optimiser les opérations commerciales. L'entreprise est enregistrée et autorisée en tant qu'institution de monnaie électronique par plusieurs autorités financières, y compris la FCA du Royaume-Uni et la Banque de Lituanie, et agit en tant qu'ISO aux États-Unis. Servant des industries telles que l'eCommerce, le commerce de détail, les biens numériques, les services financiers, le voyage et le jeu, elle s'engage à améliorer les taux de conversion et à atténuer les risques pour sa clientèle mondiale.

Description

• Define and maintain the information security strategy, standards, and roadmap, aligned to applicable regulations, rules, and security best practices. • Steer security architecture across a cloud-native environment, defining secure-by-design patterns for microservices, APIs, and shared platform services. • Establish and govern secure software development lifecycle (secure SDLC) practices, embedding automated security controls into CI/CD pipelines. • Define and drive adoption of cloud security guardrails - identity, network segmentation, encryption, secrets management, and configuration baselines. • Build and run security monitoring, logging, and threat detection across cloud, infrastructure, and application layers. • Lead the security incident response lifecycle - preparation, detection, containment, eradication, recovery, and post-incident review - and act as incident commander for security events. • Own vulnerability and threat management: scanning, risk-based prioritization, remediation tracking, and reporting across infrastructure, containers, and application code. • Plan and coordinate penetration testing and offensive-security exercises (in-house or co-sourced) and drive findings to closure. • Govern identity and access management, privileged access, and least-privilege principles across cloud and corporate systems. • Define and oversee data protection controls - encryption, key management, data classification, and loss prevention - for sensitive and cardholder data. • Secure corporate IT and office infrastructure, including endpoints, networks, and productivity and collaboration platforms. • Partner with Engineering and DevOps teams to make the secure path the easy path, providing tooling, standards, threat modelling, and design reviews. • Provide security input into architecture and change decisions, including the adoption of new technologies and third-party services. • Run security awareness and phishing-resilience programs for technical and non-technical staff. • Implement and evidence the technical security controls underpinning PCI DSS, ISO 27001, and SOC audits. • Monitor the evolving threat landscape and emerging security technologies. • Act as a key member of the internal security center of excellence and contribute to cross-functional security working groups. • Build, lead, and mentor a small security team. • Report security posture, key risks, and metrics.

🎯 Exigences

• Bachelor’s or master’s degree in computer science, information security, or a related field, or equivalent practical experience. • At least 10 years in information / cyber security, including a minimum of 2-3 years in a leadership role, with hands-on experience securing cloud-native environments at scale. • Deep, practical public-cloud security knowledge (AWS strongly preferred): identity, networking, encryption, logging, and configuration management. • Strong experience securing DevOps / CI/CD pipelines and modern microservices architectures - containers, APIs, and infrastructure-as-code. • Working knowledge of application security and secure SDLC across modern programming languages and web frameworks. • Hands-on experience with security operations, incident response, and vulnerability management. • Solid understanding of security frameworks and compliance standards relevant to payments: ISO 27001, PCI DSS, SOC 2, and NIST CSF. • Working AI security literacy, with hands-on use of AI-assisted security tooling (e.g., GenAI coding assistants, AI-augmented SAST/DAST and SIEM/SOC analytics) and a practical understanding of securing AI/LLM and agentic applications, including AWS AI services such as Amazon Bedrock and the OWASP Top 10 risks for LLMs (e.g., prompt injection and data leakage). • Strong analytical and problem-solving ability, with high integrity and sound judgement. • Excellent verbal and written communication skills, fluent English, and the ability to influence engineers with data, logic, and best practices.

🏖️ Avantages

• Fast-growing payment company; • Excellent working conditions, casual atmosphere, and state-of-the-art hardware; • Modern, challenging, constantly growing business; • Professional development - books, trainings, certifications, etc.; • Team buildings and fun activities; • 25 days paid holiday, 1 day for every 2 years with us; • Fully distributed and remote.

Postuler Maintenant